Show filters
121 Total Results
Displaying 41-50 of 121
Sort by:
Attacker Value
Unknown

CVE-2022-45892

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.
Attacker Value
Unknown

CVE-2022-45891

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
Attacker Value
Unknown

CVE-2022-45890

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).
Attacker Value
Unknown

CVE-2022-45889

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
Attacker Value
Unknown

CVE-2022-28452

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2022-27850

Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
Attacker Value
Unknown

CVE-2022-27849

Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
Attacker Value
Unknown

CVE-2021-42255

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
Attacker Value
Unknown

CVE-2022-1165

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.
Attacker Value
Unknown

CVE-2022-25601

Disclosure Date: February 25, 2022 (last updated February 23, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).